PT-2005-2900 · E107 · Eping Plugin

Oliver Monneke

·

Publicado

2005-06-14

·

Atualizado

2024-02-14

·

CVE-2005-1949

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ePing plugin for e107 portal (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping host parameter in the eping validaddr function.
Recommendations For the ePing plugin, consider restricting access to the eping validaddr function until a patch is available. Avoid using the eping host parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1949

Produtos afetados

Eping Plugin